Many business owners believe they have a firewall because they have a router from TDC or YouSee. This is a widespread misconception, and an expensive one. A consumer-grade router can share an internet connection and may block a few obvious ports, but it has no understanding of what actually happens inside the traffic. That is precisely the difference a proper enterprise firewall makes.
Your router is not a firewall
A typical broadband router operates at the network layer: it sees IP addresses and port numbers, but it does not inspect packet contents. This means an attacker sending malicious code wrapped in normal HTTPS traffic on port 443 passes through without a problem.
A next-generation firewall (NGFW) goes far deeper. It inspects traffic all the way down to the application layer, understands what is being communicated, and can make decisions based on content, not just addresses and ports. It is the difference between a guard who checks whether you have a ticket and one who also looks inside your bag.
Important to know: Over 90% of all business traffic today runs over encrypted connections (HTTPS/TLS). A firewall that cannot inspect encrypted traffic is in practice blind to the majority of what passes through the network, and attackers know this well.
What should you look for?
When evaluating firewalls for a business with 10–100 users, there are several functions that should be at the top of the list:
- IPS (Intrusion Prevention System): Detects and blocks known attack patterns in real time. Without IPS, an attacker can exploit vulnerabilities in systems even if the port is open for legitimate reasons.
- Application Control: Lets you control which applications are allowed to use the network, regardless of which port they use. For example, you can allow Teams while blocking unauthorized file-sharing services.
- SSL/TLS inspection: The ability to open, inspect and re-encrypt encrypted traffic. Without this feature, the firewall is effectively blind to modern threats.
- VPN support: Secure remote access for employees working from home or on the move. A good NGFW handles this centrally and with strong encryption.
- Centralized management and logging: The ability to see what is happening on the network, receive alerts and adjust policies from a single, unified overview.
Sizing considerations and what works for SMBs
For businesses in the range of 10–100 users, it is important to choose a solution that is correctly sized. An oversized and overly complex solution requires dedicated IT resources to operate. An undersized solution creates bottlenecks during peak loads and lacks features.
Parameters that determine the choice include the total number of concurrent users, the amount of encrypted traffic to be inspected (which requires CPU power), the number of VPN connections, and whether the business has multiple locations that need to be securely connected.
For businesses in the 10–100 user segment, Check Point is one of the platforms that consistently performs best in independent tests, and is designed to be managed without a dedicated security team. Check Point's Quantum series combines a high level of protection with a management interface that is understandable to a generalist IT partner. As a CCSM Elite-certified partner, we work with Check Point solutions every day and know what works in practice for mid-sized Danish businesses.
The most important advice is to view the firewall as an investment requiring ongoing maintenance, not a one-time purchase. The threat landscape changes constantly, and a firewall that is not updated with new signatures and policies quickly loses its effectiveness. Choose a solution and a partner who ensures that protection stays current.
If you are unsure about what your current solution actually protects you against, a network assessment is a good starting point. It typically takes a couple of hours and provides a clear picture of where the gaps are.